Linux file permissions
chmod 600: what it means and when to use it
chmod 600 lets the owner read and write the file and gives nobody else any access to it.
600
rw-------
| Who | Digit | Read | Write | Execute |
|---|---|---|---|---|
| Owner | 6 |
Yes | Yes | No |
| Group | 0 |
No | No | No |
| Everyone else | 0 |
No | No | No |
How chmod 600 works
The 6 is read plus write for the owner, and the zeros shut out the group and everyone else. There is no execute permission, which is correct for data files.
600 is the standard for secrets. SSH private keys have to be 600 or SSH will not load them, and the same care applies to .env files, database credentials and API tokens on a shared machine.
Where 600 belongs
- SSH private keys
- .env files and other credential files
- Personal data files on a shared server
The command
Both of these set exactly the same permissions. The number is shorter; the letters are easier to read back later.
chmod 600 filename
chmod u=rw,g=,o= filename
If a service needs to read the file, make that service's user the owner rather than widening the permission to 644.